summaryrefslogtreecommitdiff
path: root/sapi/fpm/tests/pool-apparmor-basic.phpt
blob: 53245b7ea7d1ee1eb01954b4d882b4a5c348adc5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
--TEST--
FPM: AppArmor basic test
--SKIPIF--
<?php
include "skipif.inc";
$config = <<<EOT
[global]
error_log = /dev/null
[unconfined]
listen = {{ADDR}}
pm = dynamic
pm.max_children = 5
pm.start_servers = 2
pm.min_spare_servers = 1
pm.max_spare_servers = 3
apparmor_hat = a
EOT;
FPM\Tester::skipIfConfigFails($config);
?>
--FILE--
<?php

require_once "tester.inc";

$cfg = <<<EOT
[global]
error_log = {{FILE:LOG}}
[unconfined]
listen = {{ADDR:UDS}}
pm = dynamic
pm.max_children = 5
pm.start_servers = 2
pm.min_spare_servers = 1
pm.max_spare_servers = 3
apparmor_hat = a
EOT;

$tester = new FPM\Tester($cfg);
/* libapparmor has a bug which can cause SIGSEGV till Version 2.8.0-0ubuntu28
   See https://bugs.launchpad.net/apparmor/+bug/1196880
   Possible outcomes:

   - SIGSEGV|failed to query apparmor confinement
     apparmor not running
   - failed to change to new confinement
     something in apparmor went wrong
   - exited with code 70
     Change to successful; Hat not existent (Process gets killed by apparmor)
 */
$tester->runTill(
    '/(SIGSEGV|failed to query apparmor confinement|' .
    'failed to change to new confinement|exited with code 70)/'
);

?>
Done
--EXPECT--
Done
--CLEAN--
<?php
require_once "tester.inc";
FPM\Tester::clean();
?>